Feed/CVE-2025-54313
CVE-2025-54313HIGHCISA KEV: Actively Exploited

Prettier eslint-config-prettier Embedded Malicious Code Vulnerability

Published Jan 22, 2026·Updated Jan 22, 2026

NVD Description

Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

Affected Packages (8)

eslint-config-prettierNPM
From 8.10.1
Fixed in 8.10.2
eslint-config-prettierNPM
From 0.2.8
Fixed in 0.2.9
eslint-config-prettierNPM
From 0.3.1
Fixed in 0.3.2
eslint-config-prettierNPM
From 10.1.6
Fixed in 10.1.8
eslint-config-prettierNPM
From 9.1.1
Fixed in 9.1.2
eslint-config-prettierNPM
From 0.11.9
Fixed in 0.11.10
eslint-config-prettierNPM
From 4.2.2
Fixed in 4.2.4
eslint-config-prettierNPM
From 5.1.11
Fixed in 6.0.0

Public Exploits & PoCs2 found

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free